About this talk
This talk, presented by Görkem Ercan from Jozu, explores the risks associated with machine learning (ML) supply chains and introduces methodologies for enhancing security through signing, attestation, and policy enforcement. The session analyzes current ML workflows that often involve using external, unverified models, datasets, and tools, highlighting the challenges posed by limited visibility into their provenance. By adapting established software supply chain practices and utilizing OCI-based artifacts, the speaker demonstrates how to create "model kits" that enhance security in AI systems. The discussion also covers runtime enforcement mechanisms implemented in a microVM-based execution environment to ensure that only verified components are executed, thereby mitigating risks related to ML supply chain vulnerabilities.